Multi-Factor Authentication (MFA)

Multi-Factor Authentication (MFA) adds an additional layer of security to your Haiilo account by requiring a second verification factor during sign-in.

Instead of relying solely on a password, users must also provide a verification code generated by an authenticator application. This significantly reduces the risk of unauthorized account access, even if a password becomes compromised.

This feature is available as part of the Advanced Security Add-on. Please contact your personal Account Manager for further information.

What is Multi-Factor Authentication?

Multi-Factor Authentication (MFA) adds a second layer of verification during sign-in. After entering a username and password, users must also provide a time-based verification code generated by an authenticator application.

This additional verification step helps protect accounts even if passwords are compromised, significantly reducing the risk of unauthorized access.

Any authenticator application that supports industry-standard Time-based One-Time Passwords (TOTP) can be used. Popular options include:

  • Microsoft Authenticator
  • Google Authenticator
  • 1Password
  • Authy
  • Other compatible TOTP authenticator applications

How is MFA set up for the platform?

You need the "Manage authentication providers" permission to edit these settings.

Enable MFA

  1. Go to Administration > Authentication.
  2. Open the Advanced tab.
  3. Set Multi-factor authentication to On.
  4. Save your changes.

Once MFA is enabled, users can enroll their authenticator applications and use MFA during sign-in.

Trusted device validity

Admins can define how long trusted devices remain valid. If users select Trust this device, MFA can be skipped until the configured period expires. You can define a time in days, hours, minutes, or seconds.

Leaving the setting empty means trusted devices do not expire.

Requiring MFA enrollment

Admins can decide which users or groups must enroll in MFA.

  • Enforce for all users: Set to On and all users on your platform must enroll in MFA at their next login.
  • Included users and groups: Select specific users and groups for which MFA is enforced. Only these users/groups will be required to enroll. You can select a maximum of 100 users and groups.
  • Excluded users and groups: Select specific users and groups for which MFA is NOT enforced. All users except these users/groups will be required to enroll. Excluded users are exempt, even if they also belong to an included group. You can select a maximum of 100 users and groups.

How does a user enable MFA?

Users can enable MFA directly within their account settings.

  1. Open the user drop-down menu and select Account Settings.
  2. Navigate to the Multi-Factor Authentication (MFA) section.
  3. Select Enable.
  4. Re-enter your password to confirm your identity.
  5. Scan the displayed QR code using your preferred authenticator app.
  6. Alternatively, enter the provided secret key manually.
  7. Enter the verification code generated by your authenticator app.
  8. Optionally assign a name to the device.
  9. Complete the setup process.

Once setup is complete, the registered MFA device will be displayed in your account settings.

How does signing in work?

After MFA is enabled, users are prompted for an additional verification code during sign-in.

  1. Enter your username and password.
  2. Enter the verification code generated by your authenticator application.
  3. Complete the sign-in process.

After a successful MFA verification, users can choose to trust the current device.

When a device is trusted, MFA verification will not be required again in the same browser on that device. The trusted status applies only to the specific browser and device combination and can be revoked at any time from Account Settings.

This provides a smoother login experience on regularly used devices while maintaining strong account security.

Managing trusted devices

A user can view their trusted devices within their Account Settings. 

Here, they can remove devices that are no longer used, or revoke trust for a device at any time. Once trust has been removed, MFA verification will be required again during the next login from that device.

Trusted devices and logins can also be reviewed and removed by admins in Administration > User Management. 

If a user loses access to an authenticator application, replaces a mobile device, or is unable to complete MFA verification, admins can remove existing MFA device registrations. 

Frequently asked questions

  • Any authenticator application that supports industry-standard Time-based One-Time Passwords (TOTP) should work. Examples include Microsoft Authenticator, Google Authenticator, 1Password, and Authy.
  • No. If scanning the QR code is not possible, you can manually enter the provided secret key into your authenticator application.
  • Not necessarily. If you choose to trust a device, future logins from that browser on the same device may not require MFA verification.
  • Yes. Trusted devices can be reviewed and removed from Account Settings at any time.
  • Contact your admin. Admins can remove existing MFA device registrations. After removal, you will be prompted to register a new authenticator application during the next MFA enrollment process.
  • Yes, admins can enforce MFA for all users in Administration Authentication Advanced.

Security best practices

To get the most benefit from MFA, Haiilo recommends:

  • Enable MFA whenever possible.
  • Protect access to your authenticator application.
  • Never share verification codes.
  • Remove trusted devices you no longer use.
  • Secure your mobile device with a PIN, biometrics, or both.
  • Report suspected unauthorised account activity immediately.

Was this article helpful?

0 out of 0 found this helpful